CVE-2019-7331
Summary
| CVE | CVE-2019-7331 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-04 19:29:00 UTC |
| Updated | 2019-02-05 13:42:00 UTC |
| Description | Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Self - Stored Cross Site Scripting (XSS) - monitor.php · Issue #2451 · ZoneMinder/zoneminder · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199513 Ubuntu Security Notification for ZoneMinder Vulnerabilities (USN-5889-1)
- 502205 Alpine Linux Security Update for zoneminder
- 505604 Alpine Linux Security Update for zoneminder